CURRENT MISSION: Conclude the 2026 soyjak.party hack page, aswell as any pages relating to it, such as the Summer 2026 Crisis page.
Update Quotecord with any relevant info. See the blackboard for more info.

Operations security

From Soyjak Wiki, the free ensoyclopedia
Revision as of 16:29, 12 August 2026 by PNWjakker (talk | contribs) (https://www.washingtonpost.com/news/the-switch/wp/2013/10/05/the-nsa-is-trying-to-crack-tor-the-state-department-is-helping-pay-for-it/ (They already have))
Jump to navigationJump to search
>Though maybe you were looking for OPSEC DEMON?
Warning! The following may feature disinformation, psy-ops, or other infohazards.Proceed with caution.
This page is a gem.
Kaboom! There goes your tower, watch it crumble, feel the power! Hairytwinkle's in the game, no escape! Time to face your fate, there's no debate!
Op seck? What's that, man?
Loose lips might sink raids.

OPSEC, short for Operations Security, is a set of practices that help hide sensitive information from adversaries and other bad actors who could potentially use it to find out who you are.

Lesotho is the best country to use a VPN for avoiding bans on The Sharty.
OPSEC DEMON

Why you should care about OPSEC

Most normgroids will usually bring up the same two excuses:

>I have nothing to hide, I don't mind!
>They need a warrant to search my things!

In reality, surveillance systems, data brokers, and large corporations collect massive amounts of data regardless of intent. Governments can obtain access through legal frameworks, while corporations monetize user data for profiling and targeting. Even "community websites", such as 4chan or the Sharty, need to collect data for things like ban evasion detection and combating spam.

Regardless of who it is, small pieces of information can be aggregated over time to build a complete identity profile. It may sound like a complete sci-fi dystopia, but some of the methods they have been known to use for data collection include using high-pitched tones only electronic devices can hear that are known to report how many people are watching a TV show[1], collecting your banking and shopping info[2], tracking your car IRL as you drive[3], tracking your phone's physical location as you browse a store[4], the DMV selling your driver's license info[5], and LITERALLY STEALING YOUR DNA from family heritage testing services[6].

Now, disregarding the obvious fact that you're a smart 'teen and you need OPSEC for doing your regular 'teen activities, there are many real reasons as to why OPSEC really matters in the real world.

  • In 2017, the FBI chose to drop charges against a pedophile rather than reveal how they caught him so whatever backdoor they used wouldn't get patched. This demonstrates that their claims of mass surveillance to "protect children" aren't always true.[7]
  • Major financial institutions have been known to penalize some individuals just because they didn't like their spending habits. An example is when American Express lowered someone's credit limit because they shopped at Walmart.[8]
  • Modern cars abuse their internet connectivity by tracking your driving habits, selling the data to brokers, and having them calculate your insurance rates, sometimes incorrectly.[9]
  • Ring doorbells are known to be used by police as surveillance networks.[10]
  • Lack of privacy leads to a population that is afraid to educate themselves on important issues, lest they be mistaken for troublemakers.[11]
  • The FBI, in 2020 and 2021 alone, abused Section 702 of the Foreign Surveillance Intelligence Act to spy on people 278,000 times.[12] Imagine this. You're texting your friend when he adds you to a group chat with Abubakr Shekau. Now, the FBI is allowed to completely invade your privacy. This includes the Character.AI goon sessions, you sick fuck.

What is OPSEC?

OPSEC centers on three things: privacy, security, and anonymity. It is easy to confuse these three things with one another, but they are not the same.

  • Privacy is your ability to ensure that your data is only accessed by you and others who have permission[a]. Privacy means your messages cannot be seen by anyone other than you and the recipient. Privacy means information that you provide to a website, such as your email or password, is hosted securely. Privacy is the freedom to not have your activity be logged and monitored. Privacy is secrecy; you close the door when you go to take a shit. Everyone knows what is going on in there, and yet you still don't want it to be seen. Just because >99% of everything about you is SNCA doesn't mean you should ignore privacy.
  • Security is being able to trust your hardware and software. Secure hardware is increasingly becoming a thing of the past, and not much can be done about it. Secure hardware also primarily concerns law enforcement and even "offline" OPSEC, like not leaving your PC open when you're outside. Secure software, on the other hand, is far more manageable. It involves using trustworthy operating systems and programs, nuking telemetry, and configuring security features properly.
  • Anonymity is keeping your real identity fully separate from your online identity. Anonymity comes in different forms: keeping your personal information segregated from your online identity allows you to avoid being doxxed. Technical anonymity allows data that identifies you (or your location or device), such as your IP, to be hidden not only from others, but from sites and other groups as well. OPSEC demons mainly fail at this part. 'teens have encountered many abominations that have good privacy and security but fail at anonymity because they're usually unable to keep their ego in check and separate themselves from their online identity. If you are interested in doxxing someone, this is where you strike.

Good OPSEC practice ensures that you pay attention to and balance these three concepts. It does not mean that you only focus fully on one concept (aforementioned abominations don't care about anonymity as much, for example).

Think of a random groomer who has been delivered lots of 'za. Groomers tend to be scared of law enforcement and the Sharty, and therefore try to use private and secure platforms. Yet, because of their inability to function properly as human beings, they will still share identifying information with others when attempting to groom or engage in other antimatter behavior. Don't mirror this behavior and attach bits of your real identity to your online identity.

This article is therefore split into three categories, and it is advised that you read all three of them. If you are not interested in OPSEC, for some reason, or only want to learn more about doxxing others using a backward approach, read the anonymity section, as doxxing someone through a privacy or security "attack" is rather rare.

Always remember that nothing is ever fully secure. As a final note, remember that this page may not have the most up-to-date information.

Guide

Know Your Enemy

Before getting into the details of OPSEC, it is important to understand whom and what you're defending against. OPSEC is a set of careful precautions based on these risks, not turning on a VPN and calling it a day.

Glowies
Glowies love to monitor the situation on the Sharty.
If you have nothing to hide, you have nothing to fear nusoi!

Glowies are both the biggest and most effective threat against you. If you do anything that gets you into IRL trouble, glowies will 'nish you and do things to you never done before. Glowies have three goals: centralization, surveillance, and deanonymization.

Centralization is simple. Glowies don't want you to use websites that are not datamining, tranny, and AI-spam friendly, such as the Sharty. They will do everything to consolidate the internet's userbase into shitty sites like Twitter, Reddit, etc., to make spying on you even easier.

Surveillance is the action taken by glowies to ensure there is nothing threatening on a site. For example, after 4chan's Super Bowl incident in 2006[13], glowies began surveillance of the site that continues to this day. It is very safe to assume the Sharty is being monitored as well.

Deanonymization is how glowies figure out who you are for 'nishing you IRL. There are so many methods that they can use, including secret, unknown methods (remember the pedo who walked away because the FBI refused to disclose how they backdoored him). Take a look at this page to see the lengths they can go to deanonymize someone.

However, glowies are not particularly interested in literal whos. Their usual targets are pedos, terrorists, drug dealers, and other criminals, and they will not go to the lengths described above to deanonymize you unless you provoke them by severely breaking the law. Instead, they rely on usual datamining and corporate datamining to keep an eye on you while engaging in other behavior, like psyops. In this case, think of them as a sleeping bear: you really need to provoke them to suffer consequences. Refrain from doing that.

Corporations
>mmm browser history data, time to sell this to Israel

Surveillance capitalism, also known as datamining, seeks to gain profit by selling your data, such as your browsing habits, shopping habits, and online behavior. Corporations are also shackled to the glowies and will cooperate with them and hand over all data they have on you upon request.

Tech corporations, like JeetSoft, are also your enemies because they ruin your security with jeetcoding and fed-ordered backdoors and datamining built into your hardware and software. By leaking your data everywhere, they also further compromise your privacy.

Seething Trannies
Trannies, despite playing victim 24/7, will try to dox you in return if they can.

>I HATE YOU CHUDS IM GONNA MONITOR YOUR NAZI SITE HOW DARE YOU DOX ME AFTER I GROOMED KIDS-AAAAAACCCKKKKKKKK

Seething trannies pose the biggest risk to your OPSEC, particularly your anonymity. Trannies, fags, pedos, splinters, etc., are the most motivated malicious actors who are seeking retaliation against you. Motivation is a huge factor in doxxing; there are seething trannies on the Sharty, 'ru, and 'ki right now sniffing around for info to dox you, chud.


Protecting your information against these actors requires, as mentioned earlier, a good, balanced combination of privacy, security, and anonymity. Measures are not equally effective; for example, blocking ads helps you protect yourself from corporate datamine rape, but does virtually nothing to stop a troon.

Privacy

>Don't read this antisemitic coal and let us datamine you and sell all your data

Privacy is secrecy, or, a bit more broadly, being able to keep yourself and information about you free from observation. Therefore, good OPSEC etiquette regarding privacy means minimizing information you leak that can be collected or exposed.

Browsers and Search Engines

Browsers and search engines are becoming an AI-infested, jeet vibe-coded, useless mess whose only goal is to sell your data to Israel instead of showing the fucking page that you want to access and use. Using a good browser and search engine is not just about OPSEC; if you value your online experience, use good variants of both.

  • Use a privacy-focused browser:
    • Mullvad Browser - Co-developed with the Tor Project. Doesn't allow you to use .onion links doebeit.
    • LibreWolf - Has uBlock Origin and anti-tracking configurations pre-installed, good for normalGOD use as well.
    • Helium - Has uBlock Origin and anti-tracking configurations pre-installed, good for ChromeGOD if you don't use Brave as well.
    • Brave - Creator Hates troonsπŸ—οΈ possible honeypot.
    • Firefox (with arkenfox user.js) - Best choice for people who want full control over their browser config and don't want to rely on any Firefox forks.
    • Ungoogled Chromium - Good for all the nusois who can't imagine themselves using something not (((Chromium)))-based. You VVILL set your flags first[b] A guide for hardening Chromium browsers can be found here.

Or...

Tor is a browser unlike the ones above it. Through the decentralized Tor network, it will provide you the highest level of privacy possible. If you are interested in learning more, click here. Keep in mind that due to the way the Tor service works, sites will know you are using it, and CAPTCHA rape you and limit or block your access.

Both Brave and Mozilla have made numerous questionable decisions that may impact privacy.

  • Switch your default search engine to a privacy-focused one
    • DuckDuckGo uses Bing as its indexing dataset; image results are often lacking. It also has an AI model wrapper called Duck.ai, supposedly without any tracking[supposedly][14]. It got caught using Microsoft trackers back in 2022.[15]
    • Searx - A metasearch engine, aggregating the results of other search engines. Can be self-hosted.
    • Qwant - Another metasearch engine; it has results similar to Bing but lacks information regarding certain websites and image searches.
    • Startpage - a Google-based search engine without the tracking, similar in concept to the Ungoogled Chromium browser. Good for NormalGOD usage as well.
  • Use incognito mode, as this gives you a clean browser state that doesn't contain any saved logins. If saved logins are compromised, an attacker will have access to your accounts without your username, password, or two-factor authentication code. You do not want your personal accounts to be compromised because you accidentally clicked on a malicious link.

Do not install any extensions that promote "privacy" other than uBlock Origin (except NoScript if you need it). Installing other, non-privacy-related extensions will impact your privacy.

JavaScript

Turning off JavaScript is an extreme measure as it will break virtually every site.

JavaScript is a programming language that the internet runs on, along with HTML, CSS, and PHP. Almost 99% of websites today use JavaScript.

Though it has been vilified by many oldfags as the devil, JavaScript is not necessarily a bad thing. It is simply the code that the internet runs on. Like all code, it can be malicious, and JavaScript is the primary vector for tracking and identifying you. Leaving JavaScript on does not mean you will be instantly deanonymized, but it does mean your activities will be traced. If you need to visit a dangerous website and make sure you are not raped in any way, turn off global JavaScript temporarily or only for that site.

A guide on how to do so can be found here for Firefox (using uBlock Origin) or here. Don't bother on Chromium-based browsers; if you need to do this, use a Firefox-based browser.

DNS

DNS (Domain Name System) is a service that translates a link (such as https://soyjakwiki.org) into an IP address (104.21.47.23[c]) for your computer to actually understand what site you are looking for. By itself, this is not a problem. However, by default, all DNS queries go through your ISP (Internet Service Provider), which allows them to log every domain you visit (this is required by law in many countries). This log can be subpoenaed, sold, or breached. Depending on where you live, certain websites might be blocked by law as well, which is achieved by your domestic DNS refusing to respond to that site query.

Recommended DNS providers are:

There is a somewhat popular belief that changing your DNS helps privacy, but this is not the case. While you can (and should) change your default DNS, standard DNS traffic is unencrypted and will still be logged regardless. Using a VPN or the Tor network will encrypt DNS traffic, which is more than enough for 'teens. However, this is still not secure, as TLS handshakes still leak domain names and allow anyone to see which domains you are connecting to, even if the DNS is encrypted. This can be resolved by using a browser that supports [ECH], but its use is limited because, ironically, it only works with sites that are hosted by Cloudflare.


But the best DNS setup for maximum opsec is to host your own DNS filtering system via pihole + unbound. What makes it giga is the fact that with this setup your ISP won’t know what you are doing, Google will not know what you are doing, and Cloudflare will not know what you are doing. This essentially makes any website you visit invisible, at least as far as we know.

Avoiding Fingerprinting and Datamining

You can use https://coveryourtracks.eff.org/ to check fingerprint uniqueness.

Fingerprinting is a tracking and datamining technique that collects details such as what browser you are using, your operating system, hardware information, screen resolution, and your time zone to figure out who you are. This can be saved as a unique identifier and allows the site to keep track of you even if you use a VPN, as these details do not change. Clearing your cookies and browsing history is also, for the most part, useless. This makes fingerprinting quite effective, as saving what may appear as mundane data like time zone and language can actually narrow down who you might be. Fingerprints are usually used to detect ban evaders and other undesirables; they can (and presumably do) get shared across sites to literally track what sites you visit and what you do on them, etc.

Avoiding fingerprinting requires you to give up many things, and therefore a browser that is resistant to fingerprinting is not good for NormalGOD usage. You have to give up:

  • Browser extensions (uBlock is all you need)
  • Browser timezone
  • Image canvas (your image clipboard)
  • Cookies
  • and more actual SNCA

tl;dr install one of the recommended browsers and don't add 50 brap extensions and tinker with settings you don't know about. Just keep the browser as-is and do your normalGOD shit on Google Chrome.

Metadata

> we kill people based on metadata[16]. <
Michael Hayden, former NSA Glowie-In-Chief

Today, cryptography is the basis for all your privacy, security, and anonymity online. It, along with the right etiquette and behavior that you will read through this page, secures you from any adversary who does not have access to the resources of a state. However, cryptography has one key weakness: it cannot be used to protect metadata. As such, the glowie solution to encryption and overall good OPSEC is no longer as reliant on backdoors, sting operations, hacking, etc. Instead, metadata is the foundation of all modern digital forensics and glowie investigations. Metadata cannot be "privatized", "secured", or "anonymized". Metadata is in everything you do online or on your device. Some metadata can be removed, like EXIF, but some cannot, like the presence of traffic at a specific time going through your ISP's infrastructure, your and your device's physical coordinates, and much more.

Metadata is not a new thing either, and has been responsible for being the key piece in investigations, ruining lives, and causing deaths. Here's a list of the worst:

  • In 2003, a totally independent dossier prepared in UK regarding Iraqi nuclear weapons contained undeleted revision history that leaked government employee names, proving it was fake[17].
  • In 2012, while John McAfee was hiding from the authorities, a Vice journalist's EXIF data of a picture he took during an interview nearly got him 'nished [18].
  • In 2013, Edward Snowden proved that:
    • MUSCULAR, a joint NSA-GCHQ operation, intercepted Google and Yahoo user data traffic and saved millions of user data.
    • PRISM is used to collect internet communications from US internet companies.
    • XKEYSCORE, used by the NSA, searches, analyzes, and processes global data 24/7.
    • The metadata in the information collected is more than enough to sketch the identity of tens of millions, and the data still is probably the foundation of such analysis today.
  • Bad metadata OPSEC by Russian soldiers in Ukraine (like sharing pictures of where they are stationed and publishing them online) has been causing them to get killed since 2015[19].
  • A 2016 Russian hacker's single accident, leftover metadata, blew an entire alleged hack that stole all of the DNC's email server, a scandal that snowballed into a disaster that decided an entire election. This would eventually be the starting point of an investigation that would derail Trump's presidency and lead to his impeachment as well[20].
  • In 2017, The FBI 'nished a NSA documents leaker by tracing her through invisible dots left by a printer she used to print sensitive information[21].
  • Since 2019 and far earlier, Israel has used metadata to kill people[22].
  • In 2026, during the Iran war, the US government claimed Iran, a country being bombed to smithereens, could "assess in near-real time" the location of US soldiers through cellphone metadata footage[23].
  • and many more...


Most of these relate to embedded metadata, but think of the Russian soldiers who get geolocated and get 'nished by drones. Even if they strip their images of all embedded metadata, the inherent features within the image can be used to still locate them.

As another example, your parents know you are currently in the basement on your computer doing something, just not what exactly. The inherent meta of your location and time wasting already paints a somewhat complete picture. They may not know what you are doing, but your mom might have an idea of you doing something to do with bald men in glasses when she glances over your screen while bringing you your dinner. If the website with bald men in glasses is on the news tomorrow, she might get suspicious of you. An actual adversary can take their time, slowly collecting meta information about you to sketch a profile and 'nish you. Inherent metadata is not like embedded metadata (such as EXIF), it is a beast of its own.

Almost nothing in this guide can stop the issue of inherent metadata. Let's say you use a VPN that's connected to a server in Canada, and you live in Germany and, hypothetically, post something illegal on a site. Even though your IP is Canadian, the server knows you are posting during Central European times to the millisecond. At the same time, your ISP also knows that you were using the internet during this period, down to the millisecond, and also knows you used a VPN. Now, the US and German glowies issue a blanket subpoena to German ISPs and start digging through the data using (probably-AI powered) supercomputers and find you to match the profile, and now you're fucked. This is very similar to what happened to German 'p spammers who were using Tor in 2019[24].


For dealing with metadata in extreme scenarios, you can:

  • Use Tor with Bridges enabled,
  • Use amnesiac Operating Systems (like Tails),

As for inherent metadata, near-schizo tier advice is the only solution, such as:

  • Throwing away your phone permanently and never using services that access your location,
  • Never using personal devices in sensitive locations (like your home),
  • Going back in time when you were a caca and never making that gmail account with your real name
  • Turning into an actual ghost DO NOT RESEARCH THIS FURTHER.

These are some of the silly-sounding measures necessary to combat inherent metadata. As mentioned earlier, there's not much you can do about it.

Communication

>You will let us read your messages, because you just will ok??

Secure, private communication is not only a must for 'teen OPSEC, but is also highly recommended for your NormalGOD activity. While your main method of communication with other 'teens will be posting on the Sharty, the Boorum, the comments section of the 'Booru, the talk pages here in the 'Ki, or the IRC, there are other trustworthy ways of communicating with other 'teens and others. Do NOT use Discord for anything Soysphere-related, you will be 'nished.

You will also need to deal with the phone number problem: some platforms require you to provide a phone number for registration or use, while some of your NormalGOD activities (like banking) require your IRL number. For online privacy, consider using a burner phone.

DO NOT use your IRL phone number for 'teen activity, such as ordering 'za. Law enforcement has access to the history of every SIM card, such as where it has been, where it currently is, your phone call history, and more.

Messengers

Do NOT use any communication service that is not open-source. Closed-source platforms cannot be vetted independently and are to be considered unsafe until proven otherwise. Platforms are increasingly being forced to reduce encryption[25] and are becoming more and more unreliable.

Here are some recommendations for secure messaging platforms:

  • SimpleX: SimpleX is a highly secure messenger platform that uses a system of decentralized servers and relays that can be hosted by anyone, meaning it is somewhat similar to the Tor network. Extremely effective at bypassing censorship, SimpleX's protocol uses double ratchet encryption and has quantum resistance. SimpleX also provides metadata protection by using "unidirectional queues" for your messages. It has been independently audited numerous times[26][27].
  • Signal: Signal is a messenger platform available both on desktop and mobile that uses the Signal protocol, which provides forward-security[d] and post-compromise security.[e]. It requires a phone number for use. Signal's servers are centralized and therefore pose a security risk. Session: Switzerland-based Australaryan instant messaging app featuring end-to-end encryption, decentralized routing, and strong privacy protections that minimize the metadata you expose. Unlike Signal, you don't need a phone number to make an accountπŸ—οΈ , only relying on account IDs instead.

Or...

  • XMPP: XMPP is an open-source, highly secure communication protocol enhanced with OMEMO. Ironically, WhatsApp, Facebook Chat, and many other popular messenger platforms were built upon XMPP, yet deliberately had their security protocols and ability to communicate with other XMPP clients removed, showing you just how trustworthy they are. One recommended XMPP client is Gajim.

Avoid:

  • Discord,
  • Telegram,
  • Matrix, which is related to an Israeli company,
  • DM features in platforms like Twitter, Reddit, etc.
  • and any other similar service/platform,

These services are compromised or easily subpoenaed. But if you must, isolate your identity completely and treat the account as disposable from the start.

Phone Numbers and SMS
When buying phone numbers for verification, NEVER use a credit card or anything else; use only crypto. These services are known to be unreliable with data privacy.
  • Use a burner phone: (if phone verification is required)
    • Crypton.sh: Ireland-based service that hosts physical SIMs that are in a "cloud network". Allows you to send and receive SMS, and it can be encrypted however you prefer. Includes an interface for ease of use. Payment is accepted in BTC and XMR. Do not use credit cards to pay.
    • MoneroSMS: SMS service. Can use it through their interface or even email. Accepts Monero, BTC, and even shitcoins. Service only allows texting US/Canadian phone numbers, and is in beta.
    • VirtualSIM: Ukraine-based service with different options available. Accepts all sorts of coins.
    • If none of these suit your needs, take a look at this page, at your own risk. Always do your homework before using any of these services.

Payments

Everything here is not financial advice.

Your buying habits and methods are the number one reason why there is so much privacy rape; it's literally money. Not only is your purchase data quite valuable, it also reveals a whole lot of info about you as a person. The financial system is, by design, as anti-privacy as it can get. Payments are heavily regulated and traced for all sorts of various reasons, such as making sure the Soyim are paying their taxes, monitoring their credit score[28] and punishing the Soyim if they dare shop in the wrong store, ensuring that those 'nished by Israel don't have access to the system, and more.

Unfortunately, options for secure payments are decreasing. Nonetheless, here are your options for private payments:

Cash

Since forever, cash has been the primary means of conducting usury transactions. Cash is excellent in small, private exchanges, and is fungible, meaning it is non-unique and difficult to track. For online payments, if the vendor accepts it, sending it by mail is the best option. For example, you can pay for Mullvad using cash.

However, cash is being phased out; cash transactions exceeding $10,000 or bank transactions exceeding $3,000 must be identified and disclosed to Israel, and serial numbers can aid law enforcement in tracking your Sproke purchases.

Despite all of this, cash is still the best option for privacy, even better than crypto, provided you are not doing anything shady.

Gift Cards

Saar, surprisingly redeeming gift cards (or preepaid cards) are not bad idea if you are being concerned for your privacy. It is allow you to exchange your monies for virtual rupees, like is on Steam, allowing you to buy the Age of Bhaarat without needing credit card.

Gift cards is not have fee saar, but the preepaid card is have fee and more rules which is why India does not like, and they have anti-India things like expiry dates saar. You may also be asked to provide your Indian ID due to increasing rates of gift card fraud from Pakistan.

Gift cards also is includes rules, terms, and conditions so you must read those before is redeem, ok? Gift card abuse is may causing your gift card to be 'nished.

Some India marketpalace is allow you to exchange bitcoin saar for gift cards, allowing you to do the same conversion but with crypto.

Cryptocurrency
Everything done with Bitcoin and Litecoin is PUBLIC INFORMATION on the blockchain. It can and will be traced back to (You).
NEVER EVER SEND YOUR CRYPTO DIRECTLY FROM AN EXCHANGE TO A VENDOR.

In relation to OPSEC, the goal of cryptocurrency is to replace cash, which comes with upsides and downsides. The benefits of crypto are:

  • Decentralized, P2P network which removes the need for Israeli involvement,
  • Faster, and often cheaper, in "cross-border" transactions,[f]
  • Anonymity (if done right),
  • Security (if done right).

The disadvantages are:

  • Your shitcoin might be (is) more volatile in value than cash,
  • It is not insured,
  • It may be difficult to use for NormalGOD payments,
  • KYC (Know Your Customer), also known as KYS (Keep Yids Satisfied), a policy that aims to fully deanonymize you.


For more information, visit the Cryptocurrency page's OPSEC section.

Before moving on to the next section, absolutely check out these pages for more information about privacy:

Security

Security is protection. More broadly, it is protection that comes in two variants: hardware and software. Hardware means the actual physical components of your computer, while software is everything that runs on that hardware. For your use case, software security is far more important than hardware security.

Hardware Security

Hardware security means actions taken by you to minimize risk. There is not much you can do by yourself to actually modify the hardware.
Buy a co-pilot enabled shittop with Intelaviv and Njudea gayming parts!

Hardware security is the most "technically" advanced section of this guide, except for offline security. Most details are beyond the scope of this article; if you really want to learn more, check this site. Most "hardware security advice" is just software advice - there is nothing you can do about a backdoor built into your hardware. Act accordingly.

To begin with, offline security simply means actions you take IRL to avoid access to your hardware. This includes things such as:

  • Not leaving your PC on 24/7, especially when unattended
  • Avoiding biometric access, like fingerprints, which can easily be used against you.

Other than that, here are some tips on hardware security:

  • Hardware, such as BIOS, often receives firmware updates that improve security. It is recommended to install them.
  • Keep Secure Boot on, if possible.
  • If you use encryption for your disks, data is more secure when the entire device is OFF instead of asleep. Turn it off if you are concerned about security.
  • Your router is a key, yet often ignored, part of your security. Most routers literally use the exact same login and password and can expose sensitive information. See this site for help on improving router security.
Intel ME & AMD PSP

All modern CPUs have hidden "management engines" such as Intel's "Intel Management Engine" (IME) or AMD's Platform Security Processor (PSP). These are essentially tiny OSes running directly in your CPU as long as they are powered, and have root access to everything. They are only exploitable by feds due to backdoors built only for them and can be used to gain direct access to your PC. Simply put, it's fed spyware built directly into your CPU, and nothing can be done about it.

IME is believed to be far worse than PSP, as PSP has no proven remote management capability, and so far, no security vulnerabilities have been discovered.

Intel and AMD CPUs have had "Transient Execution Vulnerability" incidents - unfixable flaws that can be exploited.

As mentioned earlier, there is no way to disable IME or PSP fully. You can use PCs made before 2008 and the tool. This way, the ME is removed completely, but it creates new challenges for users since they are forced to use quad-core CPUs. These CPUs are not only very slow, but also use outdated instructions and other ancient-ass software, making them almost bricks.

For PCs that use Intel Core CPUs from the 900 series to the 6th generation, the cleaner tool removes most of the ME, leaving only ROMP and BUP, which are required for booting. While the ME is still active, it's better than leaving it as it was. It shrinks the size of the ME from 1.5-5Mb to ~90Kb.

For PCs that use 7th- and 8th-generation Intel Core CPUs, the me_cleaner leaves the RBE, kernel, syslib, and BUP modules that are required for booting. The size of the ME is shrunk from 2Mb-7Mb to ~300Kb.

For any PCs that use CPUs after Coffee Lake (9th generation or later), me_cleaner is not supported.

Software Security

Good OPSEC absolutely requires the use of good, trustworthy software.

Before continuing with anything in this article, please take your time to read this section and turn off telemetry on your computer. Skipping this part and following everything else in this guide will still get you owned.

Whether you are using Windows, Mac, or some Linux distros, "telemetry" data collection will be enabled by default. Turning this off is an absolute must even if you don't care about OPSEC; you are being datamined. Many default apps also have their own telemetry data collection that may not abide by OS telemetry rules; you have to turn them off as well.

Although telemetry is claimed to be "anonymized", certain collected data allows you to be deanonymized. While explaining this in full depth without excessive SNCA is impossible, the tl;dr is that, for example, in Windows, "CLSIDs" and "GUIDs" (class identifiers) allow the identification of virtually everything on your PC. These can be accessed without needing admin privileges and can even be accessed to some extent by websites.Another example is GDID (Global Device Identifier), which was used by the FBI to identify and track someone who used a VPN and had good overall OPSEC[29]. GDID cannot be turned off, but certain settings can minimize its data collection. Just Shut Telemetry Down on your PC. >sounds scary, how do I shut it down?

For Windows, follow this guide.

Operating System

>mmmmmm, tasty data from your unsecure goyware

Picking a good operating system isn't just good OPSEC; a good operating system allows you to not suffer retarded jeet vibecoding. De-bloating will not fix jeet saarcode slowing down your PC or even bricking it in the future.

For 99% of 'teens, a single "host OS" is all they need (and want), and for that, they have two choices:

  • Windows 10 no longer maintained or Windows 11 (use Home edition, it doesn't have Bitlocker)
  • a Linux distro

If you use Mac, your hardware is tied to your Apple account (which has all your personal info), and you are fucked; no amount of OPSEC will save you. It being more secure and private than Windows is meaningless if your anonymity is dead.

Windows is not a bad choice only if you remove the metric ton of coal it is shipped with. This requires you to do so many things that are beyond the scope of this article. Instead, check these sites for help:

Linux distros vary widely (i.e., "cutting-edge", up-to-date distros vs. stable, slow-updating distros) and what you should pick depends on your use case. The Linux normalGOD use case is improving greatly. A list of recommended distros by use case can be found below:

I want something similar to Windows!
  • Fedora: Has SELinux (meaning it has pretty good security), is quite modern, and is overall easy to use. Install the KDE Plasma desktop environment if you want it to be Windows-like, or GNOME if you want it to be Mac-like you faggot. If you aren't a complete caca and know how to use a computer, Fedora is a good pick. Keep in mind that it's developed by Red Hat and is updated about every six months.
  • Mint: Very similar to Windows and quite stable. Software is not as up to date as Fedora. It is the iron gemerald of Linux distros.
  • OpenSUSE: Stable, another iron distro that is preferred by some users. More advanced than Mint. If you are concerned about the downsides of Fedora, use OpenSUSE.
I want something more secure!
  • QubesOS: QubesOS is a unique OS that fully isolates subsystems of your PC into separate "Qubes". Read the site page for more information. However, it is closed source, which means it may or may not have a backdoor considering how everything is proprietary.
  • TailsOS: Tails is an OS that routes all communications through the Tor network. It is usually booted from a USB or DVD and leaves no trace.[g] It is an OS that saves nothing and is not recommended for normal use.
  • Whonix: It separates into two VMs, a workstation where you do everything, and a Tor gateway VM that handles all traffic. If you compromise the workstation, the IP still stays hidden. Read the site page for more information.
  • or any Linux distro found here
I wanna LARP!
  • Arch - your security is in your own hands; if you don't know what you're doing (you don't if you need to ask), use a distro above.


Although there is endless shitflinging on whether Windows or Linux is better (even on the Sharty), the truth is that neither is better than the other. A de-bloated, telemetry-off Windows installation is sufficient and good for normalGOD usage. Using Linux has its own benefits, but requires a good amount of experience with how to actually use a computer and more.

Unless you use Tails or QubesOS[h], your operating system choice will NOT save you from the law; encryption can (and will) be bypassed by forensics because you fucked up at some point and never realized. Do not fall into a false sense of security or do anything unacceptable in your country; you WILL be 'nished IRL. Attempting to harden your OPSEC this hard will remove any plausible deniability[i] and make things worse. Focus more on good etiquette than on simply encrypting your disk and installing a cool distro and thinking it's safe enough.

BIOS / UEFI

BIOS, or UEFI, is your motherboard's firmware that handles your hardware and launches your OS. You can enter your UEFI by pressing a specific key during the boot process to access all sorts of settings.

UEFI, by default, has no password and comes with some unoptimized settings that require you to change them. Search up your motherboard/laptop and some setting recommendations (such as XMP or Secure Boot) to improve your experience and security.

If you are tech savvy, you can replace your default UEFI to improve security and speed.

BEFORE PROCEEDING WITH ANYTHING, READ THE FUCKING MANUAL, LINKED RIGHT NEXT TO THE RECOMMENDATION, OR YOU WILL BRICK YOUR PC[j]. GRUB hardening for even more security is also linked right next to the manual.

If you don't want to use Code of Conduct-infested shit, use OpenBSD or FreeBSD instead. OpenBSD is especially aryan btw. Here is a CVS repo with OpenBSD guides, scripts, configuration files, etc.

Claims of backdoored UEFI are quite dubious.[31]

Recommended Programs

Using the right program is important for your OPSEC. It's a good idea to prefer using open-source, free software that just works and is trustworthy.

Here's a general list of various Windows programs that can enhance your safety experience and are solid upgrades over any alternative:

  • Bulk Crap Uninstaller - useful for simply uninstalling stuff you don't want. Use this to uninstall anything listed as untrustworthy in this guide.
  • VeraCrypt - VeraCrypt is an excellent, open-source disk-encryption program that can encrypt an entire disk or partition. It is recommended that you read the website thoroughly before using it.
  • LibreOffice - an alternative to the Microsoft Office suite.
  • GIMP - A free, open-source image editor.
  • YT-DLP - If you don't want to deal with coal online video-downloading websites that try to rape you non-stop with ads and malware, learn how to use YT-DLP and put an end to those issues.
  • VirtualBox - Virtual machine (VM) software for checking out distros without installing them on your machine, checking whether a file is truly safe, and more.
Dealing with malware
You can quickly check files smaller than 32MB for any malware using this site.

Although malware is no longer the niggerhell problem it used to be, you should still absolutely be on the lookout for any malicious files. It goes without saying that you should NEVER, EVER, EVER install random shit from some literal who and open it without precautions. You WILL be owned.

Malware can be hidden in files that otherwise seem innocent like PDFs, office documents, pictures, videos, and more. The Great Cuckset happened because of a malicious .PDF file. pdf files brought down 4cuck...

Windows 10 and 11's Microsoft Defender is, surprisingly, adequate enough for most cases and will be able to protect you from most basic attacks. You do not need to install a freeware antivirus, which may cause problems or make things worse since some of them will rape you with endless popups and datamine you. If you do not trust JeetSoft, Malwarebytes is a good choice.

Make sure to keep your firewall on at all times and do not tinker with it too much.

Contrary to popular belief, macOS and Linux are not necessarily safer than Windows. Linux was almost owned hard and is dealing with an increasing number of security incidents. The same precautions against installing random shit still very much apply here. Do not install Arch ever or other "cutting-edge" distros just because it sounds cool, as they are the ones most likely to be owned in the future.

Images and removing metadata
This is what EXIF data looks like. Delete this coal from your images.

Make sure to always strip image filenames by replacing each original filename with a string of random letters and numbers, and remove the EXIF data of any images you upload.

EXIF data (Exchangeable Image File Format) is a type of metadata used by cameras and smartphones.

Stripping this information is normally the responsibility of the website before it gets published, but some either do not strip it or store it for themselves before stripping it for publishing. Be sure to check for any embedded watermarks in your images as well.

To remove:

When censoring information in an image, such as by pixelating or blurring, keep in mind there are genuine methods of restoring the image, especially with AI.

Phones

Android users, please check this site.

Phones are terrible for OPSEC if used incorrectly. Use your phone for normalGOD activities only and avoid engaging in any 'teen activity as much as possible when on your phone. However, if you need one that is somewhat safe, get an Android phone and install GrapheneOS.

GrapheneOS is a custom-built Android ROM that lets you have full control over your phone, ranging from auto-rebooting at a certain time to setting a PIN prompt to pop up whenever you try to open an app. Very useful! Remember to enable the duress PIN which will wipe your device once you enter it. A quality Google Pixel goes well with it (GrapheneOS is in a partnership with Motorola now; in 2027, some Graphene Motorola phones will be released so stay tuned). Another alternative is LineageOS.

Linux phones, while experimental, are also good choices. Old phones are okay-ish when a custom ROM is installed. If your threat model involves software backdoors, then a phone with Replicant is the best choice.


Having lots of different phones may or may not impact your OPSEC...
Mobile Apps

Applications are a core aspect of mobile OPSEC. Most mainstream apps are usually closed-source or "proprietary" software, more so than on PC. Apps or websites such as YouTube, Chrome, Facebook, and even Spotify do not allow their users to view the source code of their apps. This is usually to hide their methods of data collection and any backdoors they may be hiding. There are, however, alternative open-source apps whose code is easily accessible and can be reviewed by anybody who knows how to read it. Be careful! Just because it's open source doesn't mean it's safe. Learn how to read code to make sure any apps you're using aren't subtly glowing.

Before you can install some of the apps below, you'll need an app called F-Droid. F-Droid is an app store that only hosts open-source apps. You need an Android phone to install this app, as iPhones can't install APK files. Apps that can only be installed on F-Droid will be in bold.

  • YouTube - NewPipe, PipePipe or FreeTube
  • Google Play - F-Droid or Aurora Store
  • Browser - Mullvad Browser, LibreWolf, IceCat, or Tor Browser (Remember to disable JavaScript when visiting sketchy sites!)
  • 2FA - FreeOTP++ or Aegis
  • VPN - Mullvad VPN (with M247/DataPacket servers disabled), WireGuard (needs to be installed on a VPS, as it's not a service), Amnesia VPN
  • Disk Wiping - Extirpater
  • EXIF Remover - Scrambled Exif
  • Discord - IRC Signal, Mumble, XMPP, Woodchipper
  • Email - Proton, Tuta.

Anonymity

Hello! My name is Gigachad. I live at 12345 Gemmy St, Topaz City, 54321. My favorite 'za toppings are pepperoni and mushrooms.

Anonymity is arguably the most important section on this page. After shoring up your privacy and hardening your security, which can be considered passive compared with how active you have to be in protecting your anonymity, it is important to stick to the principles recommended in this section. If you are looking to learn more about doxxing, read this section and think backwards.

Anonymity is simply the absence of any identifying information available on the internet that can be traced back to you. Anonymity begins with having proper privacy and security, which allows you to not be datamined by groups, corporations, and to some degree, the feds. Correct behavior is what primarily ensures that you stay anonymous from other literal whos online.

So far, this article has been about the technological aspect of OPSEC, and if you do not follow the recommendations, nothing can save you. Using the right hardware, software, and privacy etiquette is good, but with the wrong behavior, nothing can save you either.

So what is this correct behavior? At its simplest, it is not posting anything about yourself IRL online, ever.

But there's more to this, and it may not seem so simple. Indeed, many 'teens and people online alike want to share things about themselves, and so correct behavior also means handling what you share in a proper way. The internet has over 6 billion users, so it actually takes some degree of fuck-up to be an identifiable needle in a haystack this big.

Of these 6+ billion people, information unique to you is what differentiates you from others and ruins your anonymity. For example, if you live in France and make this publicly known, the number drops down to ~48 million. The more you share, the narrower the scope gets until something critical is revealed, like your name, and you are doxxed.

Some examples of such information are:

  • Age
  • Sex
  • Ethnicity
  • Place of birth
  • Date of birth
  • Residence and Time Zone
  • Visited countries
  • Interests
  • Hobbies
  • Education or Work
  • Health
  • Religion
  • Family
  • Spoken languages
  • Activity schedule
  • Stylometry

Some of these matter more than others. These "bits" of information can be scattered across profiles, and the connection between these profiles is what is most dangerous. Think of such connections as keywords, like a username. If you have your date of birth, time zone, and interests listed on site A, and your sex, ethnicity, and family on site B, and use the same username, your username is what connects these two profiles verifiably enough to create a unified A+B profile. The more complete this sketch is, the closer someone is to revealing your identity. Sometimes, one website is all it takes to score a bullseye and collect all this info at once.

A username may seem like an egregious example, though some OPSEC demons doxxed by the Sharty clearly prove it is not. However, it starts to get tricky, as awareness of the status of identifying keywords is difficult to maintain. EVERYTHING you post online that is "unusual", unique, or outstanding can be a keyword. Passwords are a good example of something unique: gigach@aadbabyjakkk4550! is a completely unique password string (keyword) that can be used to connect everything in which it is present. A much less obvious example is stylometry, your unique writing style. Stylometry is what revealed the identity of Ted Kaczynski when his brother recognized sufficiently distinctive phrases and words that Ted used and reported it to the FBI[32].

Some things that are not "keywords" but are still connections include profile images, profile banners, uploaded screenshots, and more. TL;DR: If you use something that is exactly the same and unique enough on two different accounts, you link them together.

You can check if any of your emails have been leaked by jeets using this site. Also check if your password has been leaked using this site. If they have been leaked, change them IMMEDIATELY.

Essentially, don't be a retard: avoid using anything directly connected to your real life and, if possible, anything indirectly connected to it. Avoid using personal emails, phone numbers, usernames, and passwords, and avoid sharing anything about yourself such as your name, precise location, job, etc. Even if your information is anonymous, using the same username on every website will make it easy for others to get a sense of who you are. Even things that appear safe, such as a password, may end up in a public leak somewhere and be used to dox you. Avoid sharing sensitive information with anyone, even your online friends, who may (and will) save anything that they might use against you tomorrow if you have a falling out.

While it's impossible (and maybe even undesirable) to remain an anonymous literal who, you have to think for yourself about what you say on the internet. Even if you think it's SNCA, it is still a breadcrumb that might just lead someone to discover who you are. If you think you have too many connections to your personal life, even just one connection, you've already fucked up. Burn your burner and start over.

It is advised that you check how 'teens have doxxed all the trannies here to get a sense of what some common weak points are.

Several 'teens have exposed themselves and potentially received a knock on the door by the feds. Examples of retardation that led to this include:

  • using their own phone number to order 'za,
  • spamming 'oxeralds on personal accounts,
  • accidentally clicking on tracking links.

Accounts

Your account on a site or program is effectively your identity on that platform. Therefore, how you create it, manage it, and delete it are crucial for keeping yourself anonymous.

Account Creation

Do not be a retard and use personal info as a password because it's easy to remember. One leak and it's literally over. Use randomly generated passwords with special characters. It goes without saying that creating accounts on random sites is a bad idea, especially if you use the same email/username, and ESPECIALLY if you use the same password. Imagine this: you use the same email and password everywhere, jeetstar.com leaks it online, another jeet gets his hands on it before it even hits breach databases, and proceeds to log in to your Amazon account (using the same email and password) and orders 500 $50 Amazon virtual gift cards. DO NOT DO THIS NUSOI or India will do things to you never done before.

Create accounts only on trustworthy websites. This minimizes the risk of your information ending up in a breach database. If you are paranoid, you can always read the biggest SNCA known to man, "Terms of Service" or "Privacy Policy".

By creating an account on a platform, your activity is effectively logged, as the site needs to save information about you. This includes things such as your IP as well. Keep this in mind while raiding.

Account Management

Always turn on authentication methods. Try to avoid methods such as text one-time codes and instead rely on authenticator apps, preferably a secure one. A password manager is recommended for this purpose, but it comes with its own risks.

Managing Multiple Identities

Managing multiple accounts and identities is good behavior, whether they comprise your IRL NormalGOD identity, your Sharty, 'ru, or 'ki identity (or identities), your gayming identity, your completely unidentifiable anonymous identity, or your temporary identity when trying to social engineer someone for the gemmiest 'ox imaginable.

How you handle this ultimately comes down to three factors: importance, purpose, and sensitivity.

Anything to do with your public identity is the most important and MUST IN ALL CASES be separate from all other identities. It is the most dangerous identity that serves your NormalGOD purposes. Do not share anything such as your social media with anyone whom you do not absolutely trust, and do NOT LEAVE ANY CONNECTIONS TO IT FROM ALL YOUR IDENTITIES BELOW.

Your private identities will differ in the three factors and how you use them. A 'teen should think of them in three ways:

  • Private identity: i.e., your gayming identity. How you handle it depends on what you do, but it is recommended not to mix it with your sensitive identity (below) as much as possible, as there are so many leak points; this is your weak point. Think of your Steam page as an example. Even if you have no identifying information, you might have an IRL friend added who has some identifying information that, by relation, doxes some info about you.
  • Sensitive identity: i.e., your namefag on the Soysphere. It requires you to be careful due to the circumstances involved, and should be separated from everything as much as possible.
  • Anonymous identity: i.e., the identity used when archiving a dox. It requires you to be fully anonymous to avoid retaliation.
Password Management

Keeping track of random long strings of text by yourself IRL by writing them down is tedious, but still a very solid way of managing your passwords. However, that is oldfag behavior and is not as secure as a properly used password manager.

A password manager is what you use to keep track of passwords, the only thing preventing literal whos from accessing your account and seeing everything it is that you do, you fuck.

Always use unique passwords for every account and do not rely on yourself to come up with a password, as you will prefer phrases that are relevant to you and therefore pose an anonymity risk. Whether you should use a randomly generated, effectively gibberish password or a "diceware passphrase"[k] is a hot debate within security circles[l]

So what should a 'teen do?

The best solution is to use a master passphrase for your password manager vault and random passwords for accounts. Although it sounds attractive because it's easy to memorize, do NOT use a combination of words that are relevant to you, i.e., dogname-city-momname-gigachad-babyjak-favoritezatopping. These words weaken security due to math; you must use words that are random. Allow your password manager to generate the passphrase instead.

First, install the KeePassXC client and follow this guide. If you find this tutorial to be too complicated or restrictive, keep reading.

It is recommended that, after doing this, you update the password of every single account that you use per the guide.

Some alternatives to KeePassXC can be found here. You may want to consider using one listed here, such as Bitwarden, to have far easier access to your passwords on things like your phone, while using KeePassXC as a backup vault instead. A tutorial for Bitwarden is here.

Account Deletion
When deleting an account, ensure there is nothing noteworthy that you aren't aware of, like a private message.
You can find info on account deletion for common sites here.

Deleting accounts you no longer use is a good idea. If you can remember some old passwords you've used, run them through a data breach database to see if there have been any leaks, and take action.

If you are a Euro, you can request a full deletion of your data from a site thanks to GDPR.

If you are concerned about safety, it is recommended to overwrite your account's details with gibberish before deleting it. Leave the account active for some time before deleting it.

Common OPSEC Misconceptions

Misconceptions and false info regarding OPSEC are dangerous and common. Below is a list of some common myths fact-checked by Snopes to be verifiably false:

  • Open-source software means it's secure.

Snopes: "Open-source" only means the source code of the program is available for all to see and review. Something can be fully malicious and open source. More importantly, open-source software can be hijacked by a malicious contributor who may try to secretly inject malicious code into the app, owning everyone even doe it was fully open source. If you would like to learn more, visit this page for an interesting read.

  • VPNs are trustworthy

Snopes: Using a VPN to access the internet is like using another route to get to your destination. You effectively shift all your traffic to a new middleman. Bad VPN providers will still just as happily datamine you and sell your data, and, in fact, are more likely to do so since they are not as legally bound as ISPs. The catch is that "good" VPN providers are:

  • still required to cooperate with law enforcement[m].
  • still required to make money. The problem is that if you don't want to be datamined, you have to pay, and without using a secure payment method, you still get datamined.

Together, these effectively mean that VPNs cannot be inherently trustworthy. Pay with Monero and use a VPN; a subpoena will still own you. The Tor service is better at dealing with this issue and is free, which removes the second point as an issue, but Tor has its own problems that are beyond the scope of this article.

  • If it looks complicated and cool, it's better!

This is not necessarily the case. Simply put, it is etiquette that matters, not the tool. There is no "best" solution or choice.

Further reading


Notes

  1. ↑ There's more to this: this isn't about consent; apps will ask if you would like to be datamine raped; you say no; you still get datamine raped. It isn't about controlling your privacy; it is about being able to absolutely trust whatever it is to not jeetleak your shit everywhere in the first place, WITHOUT asking you.
  2. ↑ Chromium-based browsers include: Chrome[duh], Opera and Opera GX, Brave, Microsoft Edge, and literally every other browser ever that (((they))) control.
  3. ↑ This is a CloudFlare IP and may not even be accurate in the future
  4. ↑ Forward security is a feature that "rotates" security keys, so that if the current key is compromised, it does not compromise past keys.
  5. ↑ Post-compromise security is a feature that prohibits glowies from decrypting future messages if the current security key is compromised, unless they compromise all those future keys too. This, combined with forward security, makes communications quite resilient against decryption.
  6. ↑ This makes feds really mad because of sanctions regime violations, and they will do everything in the future to at least curb this.
  7. ↑ Tails can still leave video memory around and requires you to JSID to be effective.
  8. ↑ Even these operating systems are not enough without precautions; there have been cases of forensic data recovery in every distro you can think of. As an example, forensics can recover data from RAM even after you wipe everything. Do not do anything that fucks with law enforcement.
  9. ↑ By law, you may (will) be required to provide the password for your super-encrypted hard disk. Congratulations, it was all for nothing.
  10. ↑ Some enthusiast motherboards have a "backup" BIOS you can switch to. That would make this safer to experiment with.
  11. ↑ This is a phrase that is easy to remember, yet hard to guess. How is this possible? Diceware passphrases are a random assortment of words. Even just six random words together means there are ~221,073,919,720,733,360,000,000 possible combinations from 7,776 unique words, a very large number. Yet, by memorizing these six words, only you know the correct order to your passphrase.
  12. ↑ This is a debate about "entropy", how unpredictable something is. A long, gibberish password is cryptographically very strong but impossible to memorize reliably. A passphrase is less strong, but much easier to remember. Here are some references for further reading: 1 2 3, which are in favor of passphrases, and 4, 5 for a more technical explanation. Snopes recommendation is just below this note.
  13. ↑ Many VPNs advertise that they are "no-log" - this is untrue; they must still comply with and hand over all data requested by the country they are operating from. Countries like the United States can absolutely request data from other countries.

Snopes

  1. ↑ https://megalodon.jp/2026-0718-1256-31/https://arstechnica.com:443/tech-policy/2015/11/beware-of-ads-that-use-inaudible-sound-to-link-your-phone-tv-tablet-and-pc/
  2. ↑ https://megalodon.jp/2026-0718-1256-32/https://www.newsweek.com:443/secretive-world-selling-data-about-you-464789
  3. ↑ https://megalodon.jp/2026-0718-1256-32/https://sls.eff.org:443/technologies/automated-license-plate-readers-alprs
  4. ↑ https://archive.ph/AoTXz
  5. ↑ https://megalodon.jp/2026-0718-1256-40/https://www.vice.com:443/en/article/dmvs-selling-data-private-investigators-making-millions-of-dollars/
  6. ↑ https://megalodon.jp/2026-0718-1256-41/https://www.businessinsider.com:443/dna-testing-delete-your-data-23andme-ancestry-2018-7
  7. ↑ https://megalodon.jp/2026-0718-1256-44/https://gizmodo.com:443/fbi-drops-all-charges-in-child-porn-case-to-keep-sketch-1793009653
  8. ↑ https://web.archive.org/web/20130412000351/http://consumerist.com/2008/12/22/amex-lowers-your-credit-limit-if-you-shop-where-deadbeats-shop/
  9. ↑ https://megalodon.jp/2026-0718-1256-51/https://www.nytimes.com:443/2024/03/11/technology/carmakers-driver-tracking-insurance.html (backup: https://cf.mickai.me/9f7ea370b125d589b39d2af6.html)
  10. ↑ https://archive.ph/YyD0d
  11. ↑ https://megalodon.jp/2026-0718-1256-52/https://theintercept.com:443/2016/04/28/new-study-shows-mass-surveillance-breeds-meekness-fear-and-self-censorship/
  12. ↑ https://megalodon.jp/2026-0718-1257-02/https://www.theregister.com:443/on-prem/2023/05/22/fbi-abused-surveillance-law-to-snoop-on-protesters-donors/1198051
  13. ↑ https://www.justice.gov/archive/usao/nj/Press/files/pdffiles/Older/brahmcomplaint.pdf
  14. ↑ https://megalodon.jp/2026-0718-1301-24/https://duckduckgo.com:443/duckduckgo-help-pages/duckai
  15. ↑ https://www.bleepingcomputer.com/news/security/duckduckgo-browser-allows-microsoft-trackers-due-to-search-agreement/
  16. ↑ https://megalodon.jp/2026-0731-1056-08/https://abcnews.com:443/blogs/headlines/2014/05/ex-nsa-chief-we-kill-people-based-on-metadata
  17. ↑ https://www.theguardian.com/uk/2003/feb/08/politics.iraq
  18. ↑ https://www.theguardian.com/world/2012/dec/03/john-mcafee-location-revealed-vice
  19. ↑ https://www.rferl.org/a/digital-investigators-disperse-fog-of-war-ukraine/27106623.html
  20. ↑ https://arstechnica.com/information-technology/2016/06/guccifer-leak-of-dnc-trump-research-has-a-russians-fingerprints-on-it/
  21. ↑ https://www.theatlantic.com/technology/archive/2017/06/the-mysterious-printer-code-that-could-have-led-the-fbi-to-reality-winner/529350/
  22. ↑ https://x.com/idf/status/1125066395010699264
  23. ↑ https://www.reuters.com/business/media-telecom/us-commander-warns-troops-their-videos-help-iran-sources-say-2026-07-29/
  24. ↑ https://www.ndr.de/fernsehen/sendungen/panorama/aktuell/Investigations-in-the-so-called-darknet-Law-enforcement-agencies-undermine-Tor-anonymisation,toreng100.html
  25. ↑ https://megalodon.jp/2026-0728-0623-06/https://www.theguardian.com:443/technology/2025/feb/21/apple-removes-advanced-data-protection-tool-uk-government
  26. ↑ https://simplex.chat/blog/20241014-simplex-network-v6-1-security-review-better-calls-user-experience.html#simplex-cryptographic-design-review-by-trail-of-bits
  27. ↑ https://simplex.chat/blog/20221108-simplex-chat-v4.2-security-audit-new-website
  28. ↑ https://web.archive.org/web/20130412000351/http://consumerist.com/2008/12/22/amex-lowers-your-credit-limit-if-you-shop-where-deadbeats-shop/
  29. ↑ https://megalodon.jp/2026-0729-0507-56/https://www.windowslatest.com:443/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/
  30. ↑ TransChat
  31. ↑ https://megalodon.jp/2026-0718-1257-28/https://te.mpe.st:443/blog/20251208-libreboot.html
  32. ↑ https://en.wikipedia.org/wiki/Ted_Kaczynski#:~:text=Upon%20reading%20it%2C%20Kaczynski%27s%20brother%2C%20David%2C%20recognized%20the%20prose%20style%20and%20reported%20his%20suspicions%20to%20the%20FBI

Operations security is part of a series on
Computing

➜ /languages

β”œ /markup/ CSS β€’ HTML β€’ XML
β”œ /low_level/ Assembly β€’ C β€’ C++ β€’ C# β€’ Holy C β€’ Rust
β”œ /high_level/ ActionScript β€’ Bash β€’ Go β€’ Java β€’ JavaScript β€’ Lua β€’ P β€’ PHP β€’ PowerShell β€’ Python β€’ Ruby β€’ Scratch β€’ SQL
β”” /tutorials/ C β€’ C++ β€’ C# β€’ Java β€’ Python β€’ Rust

➜ /software

β”œ /forums/ jschan β€’ nusoi β€’ OpenYotsuba β€’ Vichan β€’ XenForo β€’ Yotsuba
β”œ /operating_systems/ BSD β€’ Linux (Android β€’ Fedora β€’ Linux Mint β€’ Ubuntu β€’ Tails) β€’ TempleOS β€’ Windows
β”œ /applications/ Flash β€’ GIMP β€’ IRC β€’ MS Paint β€’ Paint.NET β€’ Photoshop β€’ Web Browser
β”œ /dev/ Free-software license β€’ Game development β€’ Vim
β”” /misc/ 4get β€’ Babybot β€’ CAPTCHA β€’ django β€’ Email β€’ JS Paint β€’ MediaWiki β€’ McChallenge β€’ RAID β€’ Ricing β€’ shimmie2 β€’ Snarkysnappydoxingtool.bat β€’ Soyjak Party Enhanced β€’ Systemd

➜ /cyb

β”” Ad blocking β€’ cock.li β€’ Cryptocurrency β€’ Dark Web β€’ Operations security β€’ RAT β€’ Virtual Network Computing (VNC)

➜ /misc

β”œ /file_formats/ .gif β€’ MIDI β€’ .svg β€’ .webm β€’ .webp
β”” /hardware/ Chromebooks β€’ Raspberry pi β€’ ThinkPad β€’ WiFi

➜ /ai

β”” Generative AI (ChatGPT β€’ Gemini β€’ Grok β€’ Stable Diffusion) β€’ Vibe coding

SOYNY